[source::.../var/log/splunk/SA-ldapsearch.log] sourcetype = SA-ldapsearch [SA-ldapsearch] EXTRACT-vars = Level=.+, (?Pid=.+, File=.+, Line=.+), (?.*)